Commit Graph

5366 Commits

Author SHA1 Message Date
matt335672 3e39be9c8e CVE-2026-44178: Heap overflow in xrdp->chansrv msgs
Some xrdp -> chansrv messages allocate a fixed-size buffer which
can be overflowed by a malicious RDP client.
2026-05-06 10:32:39 +01:00
metalefty c8cd758283 Merge pull request #3798 from metalefty/freebsd-ci
CI: Switch FreeBSD CI from Cirrus CI to GitHub Actions
2026-04-29 00:36:02 +09:00
Koichiro Iwao ad6c210c2b CI: Run FreeBSD CI via GitHub Actions
Resolves:   #3797
2026-04-28 11:47:13 +09:00
Koichiro Iwao e6f350ae1a CI: Remove Cirrus CI as the service is shutting down 2026-04-28 11:45:25 +09:00
matt335672 07479384a6 CVE-2026-42218: Ensure auth fails take a fixed time
Implement a constant time for password-based authentication failure.
2026-04-27 10:29:12 +01:00
matt335672 102da4f42b Merge pull request #3792 from matt335672/sig_fix
regression: Fix SEGV in xrdp when running over TLS
2026-04-20 13:47:22 +01:00
matt335672 5fa4dc02bc regression: Fix SEGV in xrdp when running over TLS
When not using classic RDP encryption, an uninitialsed pointer can be
passed to sig64_to_uint64() in development mode.
2026-04-20 13:34:09 +01:00
matt335672 0005893a93 Merge pull request #3681 from firewave/cppcheck-performance
enabled cppcheck `performance` checks
2026-04-17 16:26:20 +01:00
firewave 0410abef98 enabled cppcheck performance checks 2026-04-17 15:07:58 +02:00
metalefty f6d3d12137 Merge pull request #3787 from metalefty/security
Clarify handling of duplicate vulnerability reports
2026-04-17 21:53:46 +09:00
Koichiro Iwao 3610afd52b Clarify handling of duplicate vulnerability reports 2026-04-17 21:10:26 +09:00
matt335672 43fa055ec4 Merge pull request #3786 from matt335672/remove_ulalaca
ulalaca: Remove for now
2026-04-17 12:46:33 +01:00
matt335672 800b5f5e7c ulalaca: Remove for now
The ulalaca module for Mac  is suffering from a lack of maintenance
currently, and its inclusion is holding up the introduction of some
code quality changes. This PR removes the module for now.
2026-04-17 12:23:17 +01:00
metalefty 41f6e6b995 Merge pull request #3782 from metalefty/cifix
Supress -Wunused-function warnings
2026-04-16 07:34:23 +09:00
Koichiro Iwao 5e7a7c046d Supress -Wunused-function warnings
`sig64_to_uint64()` is only called when devel logging is enabled.
Guard the function with USE_DEVEL_LOGGING macro.
2026-04-15 21:13:29 +09:00
metalefty c3788a374a Merge commit from fork
security: Exit on failure of env_set_user()
2026-04-14 20:39:42 +09:00
matt335672 53bc57cf59 security: Exit on failure of env_set_user()
CVE-2026-32107. Prevent possible privilege escalation if setuid()
fails.
2026-04-14 11:52:28 +01:00
metalefty 7738d111d5 Merge commit from fork
CVE-2026-35512: Heap overflow in dynvc processing
2026-04-14 17:00:20 +09:00
metalefty 084eb2237e Merge commit from fork
CVE-2026-33689: Fix length check on channel open
2026-04-14 16:43:27 +09:00
metalefty 2e465c0b3a Merge commit from fork
CVE-2026-33145: Default AllowAlternateShell to 'no'
2026-04-14 15:14:20 +09:00
metalefty 16c971a437 Merge commit from fork
security: vulns in neutrinordp fragment reassembly
2026-04-14 15:07:03 +09:00
metalefty 6d1f89a919 Merge commit from fork
CVE-2026-33516 : Address potential OOB read
2026-04-14 15:01:23 +09:00
metalefty 1bacf22fb7 Merge commit from fork
Check HMAC values when non-TLS connections are used
2026-04-14 14:06:45 +09:00
metalefty 220a50b1d2 Merge commit from fork
CVE-2026-32624: buffer overflow if domain sep used
2026-04-14 09:30:27 +09:00
jsorg71 832edcab20 Merge pull request #3779 from jsorg71/instfiles_err
remove keymap file before creating sym link
2026-04-06 12:05:57 -07:00
Jay Sorg 05210adb22 use -f when creating sym link 2026-04-06 10:29:17 -07:00
matt335672 99dfacfffc Merge pull request #3755 from matt335672/gfx_resize
resizing: Simplify GFX resizing
2026-04-06 12:46:46 +01:00
matt335672 41a4af0a36 CVE-2026-35512: Heap overflow in dynvc processing
Length checking for the EGFX dynamic virtual channel is inadequate,
allowing for heap overflows to be forced by a malicious client before
authentication.
2026-04-06 12:39:32 +01:00
matt335672 6831249bed CVE-2026-33516 : Address potential OOB read
The codec list processing code contains a potential out-of-bounds
read, as the length check comes after the data is read.
2026-04-02 11:23:42 +01:00
matt335672 8e5875e438 Merge pull request #3777 from gpotter2/rename-rdpflags
Rename RDP_INFO flags to spec names
2026-04-01 09:17:57 +01:00
gpotter2 42b830f124 Rename RDP_INFO flags to spec names, add missing 2026-03-31 21:22:33 +02:00
matt335672 36fbebcb9d Merge pull request #3768 from matt335672/remove_unused_auth
sesman: Remove unused authentication methods
2026-03-26 17:55:48 +00:00
matt335672 1f34c4b37c Merge pull request #3767 from Kropyls/devel
g_tcp_connect ipv4/6 mixing fix
2026-03-23 18:23:10 +00:00
matt335672 3c131a9f5e CVE-2026-33689: Fix length check on channel open
A check for at least two bytes remaining in a buffer should be 4 bytes.
2026-03-23 17:38:38 +00:00
matt335672 8bfc79a0bc Update security reporting instructions in SECURITY.md
Clarified instructions for reporting security vulnerabilities and emphasized that the email address is not secure for such reports.
2026-03-23 14:41:33 +00:00
Matt Cunningham fcc5bd79ea g_tcp_connect fix:
- add addr_is_ipv4 helper function
- add addr_is_ipv6 helper function
- add get_socket_family helper function
- g_tcp_connect:
  - #define for MAX_PORT_STR length
  - create *addr_arg char that is used in getaddrinfo so we can do any last-minute changes directly
  - add chars host and service which are primarily used for debug logging of attempted connection points
  - calls get_socket_family to discover family of socket
  - add switch case logic for AF_INET6/4:
    - v4: just calls addr_is_ipv6 so we don't fail on a hostname input
    - v6: drop addrconfig flag and add AI_ALL so we can try to map ipv4 destinations against ipv6 socket to support varied configurations we could see
    - if an ipv4 address comes in against an ipv6 socket, we map it to try and connect anyways
  - getaddrinfo now calls addr_arg so it picks up changes that an ipv6-case may have done
  - before calling connect, use getnameinfo to get logging values for the actual host ip/port we are about to attempt a connect on - I found this useful when debugging so thought it had value to keep
- change if (res > -1) to if (res == 0): the bsd man pages for getaddrinfo only promise that it returns 0 on success, so it seems sensible to me to cover the event that an error code could be positive, which freebsd has some positive EAI_* errors based on this: https://github.com/freebsd/freebsd-src/blob/main/lib/libc/net/gai_strerror.c
- remove connect_loopback entirely:  this had several bits of logic handling ipv6 and ipv4 mixing already and ended up being redundant because of the restructuring of g_tcp_connect, which covers direct ip address char* inputs now
- add comment about OSX to IPv6 function for clarity
2026-03-23 08:21:29 -04:00
matt335672 0f2dc88541 sesman: Remove unused authentication methods
The Kerberos module and pam_userpass modules are now unused:

1) On all supported systems, PAM provides a far superior way to
   integrate Kerberos support.
2) The pam_userpass module (https://github.com/openwall/pam_userpass)
   (which is a lovely idea) is no longer maintained.
2026-03-23 11:24:19 +00:00
matt335672 b9742d94f7 Merge pull request #3764 from matt335672/regression_smartcard_removal
regression: Fix client issues with no smartcard
2026-03-18 20:24:05 +00:00
matt335672 7d618945b1 regression: Fix client issues with no smartcard
57609d4aa7 introduced an issue where
the numCapabilities field in the DR_CORE_CAPABILITY_REQ PDU
was incorrect unless --enable-smartcard was specified.

This commit also improves the logic around handling clients who
advertise a smartcard even if we do not support it.
2026-03-18 19:56:29 +00:00
matt335672 7f6e198b06 Merge pull request #3761 from matt335672/update_actions
CI: Upgrade to latest github action versions
2026-03-18 10:38:15 +00:00
matt335672 e2148a360c CI: Upgrade to latest github action versions
This has been prompted by the following deprecation messages:

> Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@v4, actions/checkout@v4.
2026-03-18 09:53:46 +00:00
matt335672 45f62bdedd CVE-2026-33145: Default AllowAlternateShell to 'no' 2026-03-18 09:26:07 +00:00
matt335672 1737f19485 Merge pull request #3758 from matt335672/disable_smartcard_code
Disable smartcard code by default
2026-03-18 09:17:08 +00:00
matt335672 57609d4aa7 smartcard: Update redirector smartcard capability
Only announce a smartcard capability in the redirector if we can
support it.
2026-03-17 15:22:11 +00:00
matt335672 7a2ac0c177 security: Disable smartcard code by default
The smartcard code contains a number of security vulnerabilities and
does not work at the moment.

The code has been left in the source tree, but moved behind an
'--enable-smartcard' configure flag which is clearly marked as not
for production use.
2026-03-17 15:22:11 +00:00
matt335672 458944983f Merge pull request #3757 from matt335672/fix_audio_modules
regression: Audio modules
2026-03-16 11:13:03 +00:00
matt335672 3444f9a1e0 regression: Audio modules
Following on from the display number removal, the code to set
the environment variables for the audio modules has been discovered
to be incorrect.
2026-03-16 10:47:46 +00:00
matt335672 b73f0f1c75 Merge pull request #3753 from matt335672/display_num_regressions
regression: Display number related issues
2026-03-16 10:00:37 +00:00
matt335672 3f0f7df6ff CVE-2026-32623: vulns in neutrinordp fragment reassembly
This PR addresses potential buffer overflows in fragment reassembly in
the neutrinordp shim by adding length and status checks.
2026-03-14 11:28:19 +00:00
matt335672 f1a2bec415 CVE-2026-32624: buffer overflow if domain sep used
Check the username buffer is not overflowed if the domain separator
feature is used.
2026-03-13 17:08:14 +00:00